reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
$ npx -y skills add zhaoxuya520/reverse-skill --skill digital-forensics --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/digital-forensicsContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
name: digital-forensics description: Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` 或组织 IR 授权说明 2. `NOW`: 确认是**取证/溯源**而非进攻性扫描 3. `NOW`: 建立 case;证据只读副本优先(原始介质写保护) 4. `NEXT`: tool-index;Volatility 等常手动 5. `ACT`: 保全哈希 → 时间线 → 关键伪影
□ 计算 SHA256;记录时区与采集命令 □ 工作在副本上;原始只读 □ chain of custody 备注写入 timeline
vol -f mem.dmp windows.info vol -f mem.dmp windows.pslist vol -f mem.dmp windows.netscan vol -f mem.dmp windows.cmdline
□ 事件日志:Security / PowerShell / Sysmon □ 持久化:Run 键、服务、计划任务、WMI □ 执行痕迹:Amcache、Prefetch、BAM
□ tshark 统计会话与 DNS □ 导出可疑流 → protocol-reverse 或 malware C2 分析
| 工具 | 用途 | |------|------| | Volatility 3 | 内存 | | Timeline Explorer / Plaso | 超级时间线 | | tshark | PCAP | | Eric Zimmerman 工具集 | Windows 伪影 | | Autopsy / FTK Imager | 磁盘 |
**上游**: MASTER R25 **下游**: 恶意样本深挖 → malware-analysis;规则 → threat-hunting
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…